📄 usersearch.php
字号:
echo " </table></td>\n";echo " <td align=left class=right_main scope=col>\n";echo " <table width=100% height=100% border=0 cellpadding=10 cellspacing=1>\n";echo " <tr class=right_main_text>\n";echo " <td valign=top>\n";if (!eregi ("^([[:alnum:]]| |-|'|,)+$", $post_username)) {if ($post_username == "") {} else {echo " <br />\n";echo " <table align=center class=table_border width=60% border=0 cellpadding=0 cellspacing=3>\n";echo " <tr>\n";echo " <td class=table_rows width=20 align=center><img src='../images/icons/cancel.png' /></td><td class=table_rows_red nowrap> Alphanumeric characters, hyphens, apostrophes, commas, and spaces are allowed when searching for a Username.</td></tr>\n";echo " </table>\n";$evil_input = "1";}}if (!eregi ("^([[:alnum:]]| |-|'|,)+$", $display_name)) {if ($display_name == "") {} else {echo " <br />\n";echo " <table align=center class=table_border width=60% border=0 cellpadding=0 cellspacing=3>\n";echo " <tr>\n";echo " <td class=table_rows width=20 align=center><img src='../images/icons/cancel.png' /></td><td class=table_rows_red nowrap> Alphanumeric characters, hyphens, apostrophes, commas, and spaces are allowed when searching for a Display Name.</td></tr>\n";echo " </table>\n";$evil_input = "1";}}if (!eregi ("^([[:alnum:]]|_|\.|-|@)+$", $email_addy)) {if ($email_addy == "") {} else {echo " <br />\n";echo " <table align=center class=table_border width=60% border=0 cellpadding=0 cellspacing=3>\n";echo " <tr>\n";echo " <td class=table_rows width=20 align=center><img src='../images/icons/cancel.png' /></td><td class=table_rows_red nowrap> Alphanumeric characters, underscores, periods, and hyphens are allowed when searching for an Email Address.</td></tr>\n";echo " </table>\n";$evil_input = "1";}}if (($post_username == "") && ($display_name == "") && ($email_addy == "")) {echo " <br />\n";echo " <table align=center class=table_border width=60% border=0 cellpadding=0 cellspacing=3>\n";echo " <tr>\n";echo " <td class=table_rows width=20 align=center><img src='../images/icons/cancel.png' /></td><td class=table_rows_red nowrap> A Username, Display Name, or Email Address is required.</td></tr>\n";echo " </table>\n";$evil_input = "1";}if (!empty($office_name)) {$query = "select * from ".$db_prefix."offices where officename = '".$office_name."'";$result = mysql_query($query);while ($row=mysql_fetch_array($result)) {$tmp_officename = "".$row['officename']."";}mysql_free_result($result);if (!isset($tmp_officename)) {echo "Office is not defined.\n"; exit;}}if (!empty($group_name)) {$query = "select * from ".$db_prefix."groups where groupname = '".$group_name."'";$result = mysql_query($query);while ($row=mysql_fetch_array($result)) {$tmp_groupname = "".$row['groupname']."";}mysql_free_result($result);if (!isset($tmp_officename)) {echo "Group is not defined.\n"; exit;}}// end post validation //if (isset($evil_input)) {echo " <br />\n";echo " <form name='form' action='$self' method='post'>\n";echo " <table align=center class=table_border width=60% border=0 cellpadding=3 cellspacing=0>\n";echo " <tr>\n";echo " <th class=rightside_heading nowrap halign=left colspan=3><img src='../images/icons/magnifier.png' /> Search for User </th></tr>\n";echo " <tr><td height=15></td></tr>\n";echo " <tr><td class=table_rows height=25 width=20% style='padding-left:32px;' nowrap>Username:</td><td colspan=2 width=80% style='color:red;font-family:Tahoma;font-size:10px;padding-left:20px;'><input type='text' style='color:red;' size='25' maxlength='50' name='post_username' value='$post_username' onFocus=\"javascript:form.display_name.disabled=true;form.email_addy.disabled=true; form.display_name.style.background='#eeeeee';form.email_addy.style.background='#eeeeee';\"></td></tr>\n";echo " <tr><td class=table_rows height=25 width=20% style='padding-left:32px;' nowrap>Display Name:</td><td colspan=2 width=80% style='color:red;font-family:Tahoma;font-size:10px;padding-left:20px;'><input type='text' style='color:red;' size='25' maxlength='50' name='display_name' value='$display_name' onFocus=\"javascript:form.post_username.disabled=true;form.email_addy.disabled=true; form.post_username.style.background='#eeeeee';form.email_addy.style.background='#eeeeee';\"></td></tr>\n";echo " <tr><td class=table_rows height=25 width=20% style='padding-left:32px;' nowrap>Email Address:</td><td colspan=2 width=80% style='color:red;font-family:Tahoma;font-size:10px;padding-left:20px;'><input type='text style='color:red;' size='25' maxlength='75' name='email_addy' value='$email_addy' onFocus=\"javascript:form.post_username.disabled=true;form.display_name.disabled=true; form.post_username.style.background='#eeeeee';form.display_name.style.background='#eeeeee';\"></td></tr>\n";echo " <tr><td class=table_rows height=25 width=20% style='padding-left:32px;' nowrap>Office:</td><td colspan=2 width=80% style='padding-left:20px;'> <select name='office_name' onchange='group_names();'>\n";echo " </select></td></tr>\n";echo " <tr><td class=table_rows height=25 width=20% style='padding-left:32px;' nowrap>Group:</td><td colspan=2 width=80% style='padding-left:20px;'> <select name='group_name' onfocus='group_names();'> <option selected>$group_name</option>\n";echo " </select></td></tr>\n";echo " <tr><td class=table_rows align=right colspan=3 style='color:#27408b;font-family:Tahoma;'><a class=footer_links href=\"usersearch.php\" style='text-decoration:underline;'>reset form</a></td></tr>\n";echo " </table>\n";echo " <table align=center width=60% border=0 cellpadding=0 cellspacing=3>\n";echo " <tr><td height=40> </td></tr>\n";echo " <tr><td width=30><input type='image' name='submit' value='Create User' align='middle' src='../images/buttons/search_button.png'></td><td><a href='useradmin.php'><img src='../images/buttons/cancel_button.png' border='0'></td></tr></table></form></td></tr>\n";include '../footer.php';exit;} else {$post_username = addslashes($post_username);$display_name = addslashes($display_name);$office_name = addslashes($office_name);$group_name = addslashes($group_name);if (!empty($post_username)) {$tmp_var = $post_username;$tmp_var2 = "Username"; if ((!empty($office_name)) && (!empty($group_name))) { $query4 = "select empfullname, displayname, email, groups, office, admin, reports, time_admin, disabled from ".$db_prefix."employees where empfullname LIKE '%".$post_username."%' and office = '".$office_name."' and groups = '".$group_name."' order by empfullname"; $result4 = mysql_query($query4); } elseif (!empty($office_name)) { $query4 = "select empfullname, displayname, email, groups, office, admin, reports, time_admin, disabled from ".$db_prefix."employees where empfullname LIKE '%".$post_username."%' and office = '".$office_name."' order by empfullname"; $result4 = mysql_query($query4); } elseif (empty($office_name)) { $query4 = "select empfullname, displayname, email, groups, office, admin, reports, time_admin, disabled from ".$db_prefix."employees where empfullname LIKE '%".$post_username."%' order by empfullname"; $result4 = mysql_query($query4); } }elseif (!empty($display_name)) {$tmp_var = $display_name;$tmp_var2 = "Display Name"; if ((!empty($office_name)) && (!empty($group_name))) { $query4 = "select empfullname, displayname, email, groups, office, admin, reports, time_admin, disabled from ".$db_prefix."employees where displayname LIKE '%".$display_name."%' and office = '".$office_name."' and groups = '".$group_name."' order by empfullname"; $result4 = mysql_query($query4); } elseif (!empty($office_name)) { $query4 = "select empfullname, displayname, email, groups, office, admin, reports, time_admin, disabled from ".$db_prefix."employees where displayname LIKE '%".$display_name."%' and office = '".$office_name."' order by empfullname"; $result4 = mysql_query($query4); } elseif (empty($office_name)) { $query4 = "select empfullname, displayname, email, groups, office, admin, reports, time_admin, disabled from ".$db_prefix."employees where displayname LIKE '%".$display_name."%' order by empfullname"; $result4 = mysql_query($query4); } }elseif (!empty($email_addy)) {
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -